Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-92355
Octopus Deploy vulnerability analysis and mitigation

Overview

CVE-2026-92355 is a path traversal vulnerability in Octopus Server that allows an authenticated user with permission to modify non built-in external feeds to overwrite arbitrary files on the server, potentially leading to remote code execution in certain configurations. It was published on September 16, 2026, and affects Octopus Server versions from 2024.1.4131 up to (but not including) 2026.1.11725, versions 2026.2.0 up to 2026.2.13344, and versions 2026.3.0 up to 2026.3.11816. The vulnerability carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Octopus Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). When a user with permission to modify non built-in external feeds supplies a crafted feed configuration, the server fails to properly sanitize path components, allowing the attacker to traverse outside the intended directory and overwrite arbitrary files on the underlying filesystem. Exploitation requires low-level authenticated access (feed modification privileges) and no user interaction, and can be performed remotely over the network with low attack complexity and no special attack requirements (GitHub Advisory, Octopus Advisory).

Impact

A successful exploit allows an authenticated attacker to overwrite arbitrary files on the Octopus Server host, compromising the integrity and availability of the system. Depending on the server's configuration and the files overwritten (e.g., executable scripts, configuration files, or startup items), this can escalate to full remote code execution, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. The vulnerability does not directly impact subsequent/downstream systems per the CVSS scoring, but RCE on an Octopus Server — which typically manages deployment pipelines and holds credentials for target environments — could enable significant lateral movement across an organization's infrastructure (GitHub Advisory, Octopus Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.684% (51st percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. No threat actor attribution has been reported. The NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable at this time.

Exploitation steps

  1. Reconnaissance: Identify Octopus Server instances running affected versions (2024.1.4131 to <2026.1.11725, 2026.2.0 to <2026.2.13344, or 2026.3.0 to <2026.3.11816) exposed on the network. Enumerate user accounts with permission to modify non built-in external feeds.
  2. Authentication: Log in to the Octopus Server with a user account that has feed modification privileges (e.g., a developer or deployment engineer account).
  3. Craft malicious feed configuration: Create or modify a non built-in external feed, supplying a path-traversal payload (e.g., using ../ sequences) in a feed parameter that is used to construct a server-side file path.
  4. Trigger file overwrite: Submit the crafted feed configuration to the server. The server, failing to sanitize the path, writes attacker-controlled content to an arbitrary location on the filesystem (e.g., overwriting a startup script, web application file, or configuration file).
  5. Achieve code execution: Depending on the file overwritten and server configuration, trigger execution of the overwritten file — for example, by restarting a service, invoking a deployment task, or waiting for a scheduled process — to achieve remote code execution on the Octopus Server host (GitHub Advisory, Octopus Advisory).

Indicators of compromise

  • Logs: Octopus Server audit logs showing unexpected creation or modification of external feeds by non-administrative users; server-side errors or exceptions related to file write operations in unusual directories.
  • File System: Unexpected modification timestamps on files outside the Octopus Server data directory (e.g., system scripts, web root files, or configuration files); presence of new or altered files in directories not normally written to by the Octopus service account.
  • Process: Unusual child processes spawned by the Octopus Server process (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) following feed configuration changes.
  • Network: Unexpected outbound connections from the Octopus Server host to external IPs shortly after feed modification events.

Mitigation and workarounds

Octopus Deploy has released patched versions addressing this vulnerability: 2026.1.11725, 2026.2.13344, and 2026.3.11816. Organizations should upgrade to one of these fixed versions as soon as possible. As an interim workaround, restrict feed modification permissions to only highly trusted users and audit which accounts currently hold permission to modify non built-in external feeds. Reviewing and tightening role-based access controls within Octopus Server can reduce the attack surface until patching is complete (Octopus Advisory, GitHub Advisory).

Community reactions

Coverage of CVE-2026-92355 has been limited to automated vulnerability tracking platforms and security news aggregators such as SecurityOnline.info, VulDB, and radar.offseq.com. No notable independent researcher commentary or significant social media discussion has been identified at this time (SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Octopus Deploy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92355HIGH8.7
  • Octopus Deploy logoOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesSep 16, 2026
CVE-2026-91778HIGH7.2
  • Octopus Deploy logoOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesSep 15, 2026
CVE-2026-14163HIGH7.1
  • Octopus Deploy logoOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesAug 20, 2026
CVE-2026-8296MEDIUM5.6
  • Octopus Deploy logoOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesJun 19, 2026
CVE-2026-12702MEDIUM5.1
  • Octopus Deploy logoOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management